Fake Russian company websites ran a nine-year scam on foreign buyers
Fraudsters cloned real Russian fertilizer and petrochemical firms, then pocketed advance payments from international customers.

Key points
- Researchers at Russian security firm F6 uncovered a fraud operation that ran for more than nine years by copying the websites of well-known Russian companies.
- The fake sites impersonated fertilizer makers, petrochemical producers and other industrial suppliers to lure foreign buyers.
- Victims were tricked into wiring advance payments to bank accounts controlled by the scammers.
- The campaign targeted international firms, not Russian consumers, which helped it stay hidden for years.
- The scheme is a classic business-email-and-invoice fraud dressed up with convincing corporate websites.
A fraud ring spent nearly a decade running fake versions of real Russian company websites, using them to trick foreign businesses into wiring money for goods that never arrived. The findings come from F6, a Russian cybersecurity vendor, and were first reported by The Hacker News.
The setup is old-school and effective. Build a website that looks almost identical to a real supplier. Buy a domain name that reads close enough to the real one. Wait for a purchasing manager somewhere in the world to Google the company, land on the clone, and start a conversation.
In practice, the mark of a good scam is that nothing about it feels weird until the money is gone.
Who did the scammers pretend to be?
The scammers cloned the websites of major Russian industrial firms, including fertilizer manufacturers and petrochemical companies. These are exactly the kinds of businesses that international buyers reach out to cold, often across language barriers and time zones, which is what makes the impersonation work.
F6 says the operation has been running for over nine years. That is not a smash-and-grab. That is a small business.
How did the fraud actually work?
A foreign buyer would find the fake site, contact what they thought was the sales team, negotiate a bulk order, and be sent an invoice asking for an advance payment. The money went into accounts controlled by the criminals. No fertilizer, no petrochemicals, no refund.
The failure mode here is entirely human and procedural. There is no clever malware in this story. There is no zero-day, meaning a secret software flaw. The whole thing runs on a convincing logo, a plausible email address, and a buyer who did not pick up the phone to verify the bank details against a known contact at the real company.
| Detail | What F6 found |
|---|---|
| Duration | More than 9 years |
| Sectors impersonated | Fertilizer, petrochemical, industrial suppliers |
| Target victims | International companies buying from Russia |
| Method | Cloned websites plus advance-payment invoices |
| Attribution | Not publicly named by F6 |
Why did this go on so long?
Because the victims were abroad and the impersonated brands were Russian, nobody in either jurisdiction had strong incentive to shut it down. Cross-border invoice fraud is notoriously hard to prosecute. Buyers in one country, sellers' identities stolen in another, bank accounts likely in a third.
One thing the post-mortem will say, again, is that domain monitoring by the real companies would have caught the clones early. Most large firms do not watch for lookalike domains registering against their brand, and the ones that do often only check the obvious typos.
What should buyers do?
If you are purchasing from an unfamiliar overseas supplier, do two boring things. Verify the bank account by calling a phone number you found independently, not one on the invoice or the website you just landed on. Then check the domain registration date. A supplier claiming 40 years of trading whose website was registered last spring is not who they say they are.
Operational takeaway: brand-impersonation fraud is a procurement problem before it is a security problem, and it stops the moment somebody insists on a verified phone call.



